Google Groups Used to Send Commands to Malware
Symantec has uncovered a scheme to use a Google Groups newsgroup to sneak commands to malware on compromised computers.
The move is another example of attackers looking for covert ways to communicate to their bots. Earlier this year, attackers were found using Twitter as a command and control (C&C) mechanism. By integrating their messages with legitimate communications, attackers make it more difficult to identify and shut down their C&C, according to Symantec.
“This technique is analogous to the use of encoding messages in newspaper ads that were commonplace in spy novels,” Zulfikar Ramzan, technical director of Symantec Security Response, told eWEEK. “What attackers are taking advantage of are online mediums that allow pretty much anyone to post content and are both highly available as well as readily accessible from the outside. I believe they are going down this route, since it represents a very easy and inexpensive avenue for setting up command and control.”